To use this cloudbuild.yaml the following pre-reqs need to be met:
- Create a invoker service account (e.g.
service-invoker@my-project.iam.gserviceaccount.com) - Grant the
Cloud Run Invoker/Cloud Function Invokerrole / permissions to invoker service account - Grant
roles/iam.serviceAccountOpenIdTokenCreatorto the Cloud Build service account for the invoker service account - Enable the
iamcredentials.googleapis.comAPI